Vulnerability index

Browse CVEs

127 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Rational Clearcase CRITICAL 9.1
CVE-2014-0931

Multiple XML external entity (XXE) vulnerabilities in the (1) CCRC WAN Server / CM Server, (2) Perl CC/CQ integration trigger scripts, (3) CMAPI Java…

Fix: after 8.0.1.3
Fix from $2,300 2018-04-20
Rational Clearquest HIGH 7.1
CVE-2014-0950

Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) Cle…

Fix: after 8.0.1.3
Fix from $1,950 2018-04-20
Datapower Gateway HIGH 7.1
CVE-2018-1421

IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing…

Fix: after 7.6.0.5
Fix from $1,950 2018-04-04
Connections MEDIUM 6.5
CVE-2015-7461

XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cau…

Fix: after 3.0.1.1
Fix from $1,600 2018-03-20
Infosphere Information Server MEDIUM 5.4
CVE-2016-0250

XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote …

Fix: 11.3.1.2+
Fix from $1,600 2018-03-12
Financial Transaction Manager HIGH 7.1
CVE-2017-1758

IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3…

Patch available
Fix from $1,950 2018-02-21
Content Navigator HIGH 8.2
CVE-2018-1364

IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exp…

Mitigation only
Fix from $1,950 2018-01-29
Rational Quality Manager MEDIUM 6.5
CVE-2016-0219

XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.…

Mitigation only
Fix from $1,600 2018-01-16
Security Key Lifecycle Manager HIGH 8.1
CVE-2017-1666

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote a…

Patch available
Fix from $1,950 2018-01-09
Security Access Manager 9.0 Firmware HIGH 8.1
CVE-2017-1477

IBM Security Access Manager Appliance 9.0.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker…

Mitigation only
Fix from $1,950 2017-11-13
Business Process Manager HIGH 8.1
CVE-2017-1527

IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attac…

Patch available
Fix from $1,950 2017-09-26
Qradar Network Security HIGH 8.1
CVE-2017-1458

IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could explo…

Mitigation only
Fix from $1,950 2017-09-05
Sterling B2b Integrator HIGH 8.2
CVE-2017-1192

IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could expl…

Mitigation only
Fix from $1,950 2017-08-10
Sterling B2b Integrator MEDIUM 6.5
CVE-2015-0194

XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers …

Patch available
Fix from $1,600 2017-08-02
Infosphere Information Server CRITICAL 9.1
CVE-2017-1383

IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remot…

Mitigation only
Fix from $2,300 2017-08-02
Bigfix Platform MEDIUM 6.5
CVE-2017-1219

IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit t…

Mitigation only
Fix from $1,600 2017-07-19
Security Guardium HIGH 7.1
CVE-2017-1254

IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit th…

Mitigation only
Fix from $1,950 2017-07-05
Api Connect HIGH 8.2
CVE-2017-1322

IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this…

Patch available
Fix from $1,950 2017-06-27
Rational Rhapsody Design Manager HIGH 8.1
CVE-2016-9698

IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML da…

Patch available
Fix from $1,950 2017-06-08
Cognos Business Intelligence MEDIUM 6.5
CVE-2016-0254

IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when proc…

Patch available
Fix from $1,600 2017-06-07
Sdk HIGH 8.2
CVE-2017-1289

IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit th…

Fix: after 8
Fix from $1,950 2017-05-22
Rational Team Concert HIGH 8.1
CVE-2017-1103

IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remot…

Patch available
Fix from $1,950 2017-05-10
Websphere Cast Iron Solution HIGH 8.6
CVE-2016-9691

IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when …

Patch available
Fix from $1,950 2017-05-05
Urbancode Deploy HIGH 8.1
CVE-2017-1149

IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when proces…

Mitigation only
Fix from $1,950 2017-04-25
Curam Social Program Management CRITICAL 9.1
CVE-2016-6111

IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when pr…

Patch available
Fix from $2,300 2017-03-31
Rational Rhapsody Design Manager HIGH 8.1
CVE-2016-9707

IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote a…

Patch available
Fix from $1,950 2017-03-31
Qradar Security Information And Event Manager HIGH 8.1
CVE-2016-9724

IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attack…

Patch available
Fix from $1,950 2017-03-07
Rational Rhapsody Design Manager HIGH 8.1
CVE-2016-8974

IBM Rhapsody DM 4.0, 5.0 and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML dat…

Patch available
Fix from $1,950 2017-02-23
Integration Bus CRITICAL 9.1
CVE-2016-9706

IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injec…

Patch available
Fix from $2,300 2017-02-15
License Metric Tool HIGH 8.1
CVE-2016-8980

IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remo…

Mitigation only
Fix from $1,950 2017-02-01